Summary
The remote host is missing an update to sendmail
announced via advisory DSA 1164-1.
A programming error has been discovered in sendmail, an alternative mail transport agent for Debian, that could allow a remote attacker to crash the sendmail process by sending a specially crafted email message.
Please note that in order to install this update you also need libsasl2 library from proposed updates as outlined in DSA 1155-2.
Solution
For the stable distribution (sarge) this problem has been fixed in version 8.13.3-3sarge3
For the unstable distribution (sid) this problem has been fixed in version 8.13.8-1
We recommend that you upgrade your sendmail package.
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%201164-1
Severity
Classification
-
CVE CVE-2006-4434 -
CVSS Base Score: 5.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
Related Vulnerabilities